smartphone, whatsapp, app, phone, social media, technology, messaging, chat, communication, mobile, internet, digital, contact, whatsapp, whatsapp, whatsapp, whatsapp, whatsapp. Message recipient, channel, device, encryption, backup, attachment, metadata, retention, and deletion checklist
Photo by antonbe on Pixabay

Maintenance

Part of Private communications guide: email, messaging, encryption, metadata, backups, attachments, and retention

Message recipient, channel, device, encryption, backup, attachment, metadata, retention, and deletion checklist

A private message checklist covering recipient identity, channel encryption, device traces, backups, attachments, metadata, retention, and deletion.

What to take away

  • Fastest pre-send orderrecipient, group membership, active mode, attachment, link permission, subject line, and whether the content is necessary.
  • Confirm the human recipient and every address, number, and group before sending; autofill picks the wrong one.
  • Check the active conversation mode, not the app's reputation. SMS, guests, bots, and business accounts fall outside end-to-end encryption.
  • Treat linked devices, lock-screen previews, clipboard history, and backups as part of the channel.
  • Inspect attachments and links separatelyhidden revisions, image location, and link permissions all leak.
  • Recall and disappearing messages are conditional controls. Microsoft's own recall page lists account, organization, and read-state conditions.
  • After a wrong send, revoke access first and notify your incident owner.

Use the pre-send list for sensitive messages. Use the full checklist when you select or review a channel.

Purpose and content

  • Purpose stated in one sentence.
  • Harm from disclosure assessed.
  • Minimum content selected.
  • Classification applied where required.
  • Record-keeping duty identified.
  • Safer channel considered if the content exceeds this one's protection.

Recipient check

Recipient Check Before Sending

  • Expand every To, Cc, Bcc, number, username, group
  • Check similar names and autofill entries
  • Consider recycled phone-number risk
  • Review group membership before sensitive content
  • Identify external guests and newly added members
  • Confirm recipient identity through a known route
  • Check reply-all scope
  • Confirm the named person, not the display name.
  • Clear wrong autofill addresses before typing.
  • Expand every group and read the full member list.
  • Check guest, external, and distribution-list members.
  • Confirm the number or handle against a second source.

Channel and mode

Channel Protection Levels

End-to-end encrypted

Examples
Signal, WhatsApp
Provider access
No message content
Metadata visible
Documented fields
Guest/bot risk
Limited
Verification
Safety number

Transport encrypted

Examples
Email TLS
Provider access
Possible
Metadata visible
Headers, logs
Guest/bot risk
Possible
Verification
Certificate

Unencrypted fallback

Examples
SMS, open email
Provider access
Full
Metadata visible
Full
Guest/bot risk
High
Verification
None
  • Record the exact product, account type, and conversation mode.
  • Confirm transport protection from current documentation.
  • Check the active conversation indicator.
  • Understand SMS, guest, bot, bridge, and business-account fallbacks.
  • Verify identity or keys when risk warrants it.
  • Understand provider, administrator, and moderator access.
  • Limit metadata claims to documented fields.

Named examples of channel modes outside end-to-end encryption: carrier SMS and MMS, a Slack guest account, a Telegram bot, a Matrix bridge, and the WhatsApp Business API. Google Messages encrypts RCS chats between Google Messages users end to end, but not SMS or MMS fallback. Microsoft Teams chat and Slack direct messages use transport encryption only.

Devices and accounts

Device and Account Hygiene

  • Update and screen-lock sender device
  • Discuss recipient device expectations
  • Review linked phones, desktops, tablets, watches, cars, browsers
  • Remove unknown sessions
  • Enable strong authentication and recovery controls
  • Assess shared devices and accessibility services
  • Know lost-device removal process
  • List every signed-in session and linked device.
  • Sign out sessions you do not recognize.
  • Check a screen lock and current updates on each device.
  • Confirm the account is not shared with another person.
  • Review app permissions for contacts, files, and microphone.
  • Confirm which device holds the local message store.

Notifications and local traces

Hide Notifications and Local Traces

  • Hide lock-screen message text if needed
  • Check desktop, watch, car, browser previews
  • Consider screen-sharing and presentation mode
  • Consider clipboard history and keyboard access
  • Check downloads, photo library, file manager, recent items
  • Review local search and device backup behavior
  • Turn off lock-screen previews for this app.
  • Hide content in notifications for sensitive conversations.
  • Clear the clipboard after pasting a code or password.
  • Remove downloaded attachments when they are no longer needed.
  • Check recent items, thumbnails, and search history.
  • Check desktop notification mirrors and shared screens.

Backups and recovery

Signal's page on backups and device transfers separates optional secure backups, on-device backups, and compatible device-to-device transfers, and it explains how recovery keys work. Read it for current Signal behavior only. Another messenger or an operating-system backup may be built differently.

  • Enable or disable backup deliberately.
  • Understand backup scope and exclusions.
  • Identify who holds the encryption key.
  • Store the recovery key away from the device.
  • Test restore with harmless data when required.
  • Separate operating-system backups from app backups.
  • Accept that recipient backups are outside your control.

Attachments and links

  • Select the correct file and final version.
  • Inspect hidden comments, revisions, sheets, layers, and properties.
  • Review image location and visible background.
  • Follow malware scanning and file policy.
  • Limit link permissions to named recipients where appropriate.
  • Set link expiration and revocation when available.
  • State download and forwarding expectations.
  • Share any password through a separate route.

Metadata

  • Keep sensitive detail out of the subject line.
  • Check that the group name and member list are appropriate.
  • Strip extra information from filenames and link titles.
  • Consider message time and frequency patterns.
  • Minimize photo and document properties.
  • Do not claim content encryption hides all metadata.

Retention and deletion

  • Match the retention period to purpose and authority.
  • Fit any disappearing timer to the record duty.
  • Include chat archives, exports, and saved media in the plan.
  • Define the member departure process.
  • Check legal hold or public-record obligations.
  • Save deletion confirmation where needed.
  • Describe remaining recipient and backup copies accurately.

Two concrete examples: keep a screenshot or export showing the deleted item, the account, and the time; and set a 24-hour disappearing timer only where no retention or legal-hold rule applies. Typical retention runs from hours to several years, set by the rule that governs the content rather than by the app.

Wrong-send response

Stop further sharing. Preserve the evidence you may need. Contact the unintended recipient through a route you already trust, revoke link access, and notify your data or incident owner. Do not forward the sensitive message to explain it; that creates another copy.

Microsoft's page on Outlook message recall lists account, organization, and unread-message conditions, and it separates recall from the short Undo Send delay on personal Outlook.com accounts. Treat recall as conditional, not as retrieval of general email.

  • Attempt recall or undo only where supported.
  • Check recall status instead of assuming it.
  • Revoke link access.
  • Ask the recipient to delete without repeating the content.
  • Notify the required incident route.
  • Assess impact and further copies.
  • Correct the autofill, delay, group, or approval control that failed.

Common questions

Should every sensitive message use disappearing mode?

No. Use it when reduced routine retention fits the purpose and does not conflict with a record duty. If a legal hold or public-record rule applies, check with the office that sets it before you rely on a timer.

Does recall delete email from every recipient?

No. Product, account, organization, and read-state conditions apply, and forwarded or copied content survives regardless. Microsoft documents these limits on its own recall page.

Should I send an attachment password in the same message?

Use a separate route when separating the password meaningfully reduces risk. If the same channel is the only practical route, say so and note the residual exposure.

What is the fastest pre-send check?

Confirm recipient, group membership, active mode, and attachment. Also confirm link permission, subject line, and whether the content is necessary at all. Those seven checks catch most wrong sends.

Where do I report a privacy complaint in Canada?

Secondary-market note: this site is US-based, and the following applies to Canada. The Office of the Privacy Commissioner handles federal complaints under PIPEDA. Quebec's access commission, Alberta's privacy commissioner, and provincial health-privacy commissioners take matters in their own jurisdictions, and a licensed lawyer can advise on your specific duty.

More in Maintenance

Latest from Guides Desk